AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
September 29, 2026

AI Pulse Daily Brief | 2026-09-29

Reading time ~15 mins

Dutch AI supervisors call their role in new compliance labs the first use of the AI Act's innovation mandate. A governance trainer shows how one AI assistant can make a bank a provider under the Act. The cabinet funds a European AI project and scales back its own AI plans. EIOPA's head separates sovereignty from concentration risk, and a World Economic Forum playbook asks lenders to price grid and water risk. Santander publishes an agent knowledge protocol, and DBS starts agents with corporate clients. Anthropic's system card shows Claude Opus 5.5 leaning on outside filters. Nate B. Jones writes on review bottlenecks, agent bills and agent fraud rules, and Intokened on the slow cost of checking AI's work. Milan prosecutors are investigating three AI-assisted frauds against Italian banks.

Regulatory

Dutch AI supervisors call their role in new AI Act compliance labs the first use of the Act's innovation mandate. Authority

Sven Stevenson wrote on 25 September for the Dutch data protection authority (AP) and the digital infrastructure inspectorate (RDI). Both supervisors have joined the third round of the AiNed ELSA Labs. These publicly funded labs build practical guides and testing tools for AI Act compliance. The post calls this a first use of the innovation mandate that comes with the AI Act. For four years, the joint AI coordination centre of the AP and RDI will link the relevant AI supervisors to lab developers. Its focus includes the AI life cycle and the design of human oversight. The brief reported the call on 25 September: up to three labs at 2.3 million euros each, with short proposals due on 30 October. Financial services is not among the four priority sectors, and the post names neither AFM nor DNB. The first supervisor-backed Dutch reading of human oversight will therefore be worked out on cases from other sectors.

AI Coalitie 4 NL (shared by Sven Stevenson)

How a business line uses a general-purpose AI tool, not the tool itself, can decide which AI Act duties apply. Independent

Aleksandr Tiulkanov, an EU AI governance instructor, wrote on 18 September that Annex III of the AI Act is "the list of high-risk use cases, not a list of high-risk systems". Articles 6(3)(d) and 6(5) of the Act also describe the list as use cases. Most enterprise AI now runs on general-purpose tools that different teams use for different ends. Turning such a tool to an Annex III purpose, such as credit scoring or screening job candidates, can trigger Article 25(1). The deploying organisation then counts as a provider, with a provider's heavier obligations. Aleksandr Tiulkanov writes that firms still often inventory AI only by asset or process. For finance and banking clients, the post adds, DORA inventory duties are often the closer concern. This is one practitioner's reading, not supervisory guidance. An AI register keyed on products lists an enterprise assistant once, even after one team points it at a credit decision.

Aleksandr Tiulkanov via LinkedIn (shared by Aleksandr Tiulkanov)

The UK government's AI risk toolkit ties every AI risk to an owner, a measurable appetite and a shutdown route. Authority

The UK Department for Science, Innovation and Technology published an AI Risk Management Toolkit on 8 September. It is written for teams that design, buy, run or retire AI. AI risk appetite is to be set per risk category, in measurable terms, and signed off at board level. Likelihood and impact are each scored from 1 to 5. A loss above one million pounds, or downtime over 24 hours, counts as catastrophic. Because an AI system has no final version, risks are reassessed whenever the model changes and monitored once it is live. A tested route to bypass or switch off the AI counts as a treatment in its own right. Jakub Szarmach, who shared the toolkit on 25 September, wrote that "AI risk registers fail when they stop at identification." On 31 July the three European supervisory authorities asked management bodies to review risk appetite thresholds for frontier AI. This toolkit shows what that review looks like when written out per risk category.

UK Department for Science, Innovation and Technology via LinkedIn (shared by Jakub Szarmach)

Perspectives

Nate B. Jones argues agents make some people far faster while their team stays behind, because review becomes the bottleneck. Independent

In a post of 27 September, Nate B. Jones describes a pattern he expects to become familiar. One person runs several agent tasks at once, yet code arrives faster than anyone can review it and decisions wait on people in other meetings. "Everybody has better tools, and finished work still waits." The usual fix, making the fast person teach everyone, can use up the very capacity it set out to spread. Nate B. Jones writes that "One person producing ten times the work for five other people to sort through is a capacity problem." He cites Cursor's spring developer report. There, the top 1% of users merged about fifteen times as many code changes as the median user. He reads that as a wide range of behaviour, not fifteen times the value. His free preview says a tenfold gain in writing code becomes a 1.8x gain for the business. An agent pilot measured on individual output can report a large gain while the review queue behind it grows. That queue decides when the business sees any of the gain.

Nate B. Jones via Substack (shared by Nate B. Jones)

Intokened argues that AI looks successful wherever results arrive fast and checking them is slow or costly. Skeptic

The publication Intokened argued on 23 September that AI deployments can look successful for months on fast measures such as time saved or volume handled. The slower and costlier checks, of accuracy, customer outcomes and later harm, arrive afterwards or are never funded. Its cases include Klarna, Meta, Coca-Cola, public-sector policing and AI-assisted coding. It proposes three questions for any deployment: what number would detect a bad result, how long that number takes to arrive, and who pays for errors in the meantime. The article draws on published company statements, research and audits, and does not say how its cases were chosen. It is the second argument in two days that AI success measures leave out the cost of checking the work, after Evident counted the checks behind each automated action on 28 September. Intokened adds timing: a bank case approved on hours saved can run for months before the evidence on credit losses or complaints arrives.

Intokened

Back from Dreamforce, Nate B. Jones argues that rising agent bills are a design problem, not a token price problem. Independent

Writing on 20 September after Salesforce's Dreamforce conference, Nate B. Jones argues that agent bills rise for two reasons that multiply. More agents are running, and each run uses more tokens, the units AI services bill by. His remedy starts from a blank sheet: the handful of value streams through which a firm wins, serves, keeps and bills a customer. Steps that existed only because one team could not read another team's system can be dropped. In his talk Nate B. Jones says "Zero is the best cost, isn't it?" What remains goes to the cheapest model and setup that does the job reliably, checked by tests of the output. The larger point is about customers. The cost of attention, Nate B. Jones writes, determined "which customers got a human being, which customers got a form". His preview says the post then follows a distributor whose smallest customers could not justify expert help before. In a bank the same cost decides which clients get a relationship manager and which get an app. A cheaper route therefore changes the service model, not only the invoice.

Nate B. Jones via Substack (shared by Nate B. Jones)

Nate B. Jones and Stripe argue that fraud and onboarding rules, not AI strategy, decide whether agents can buy. Independent

Nate B. Jones published a post on 17 September built on an interview with Stripe, the payments company. Nate B. Jones writes that "Some of the decisions that determine whether agents can use your product are being made as fraud decisions, pricing decisions, and onboarding decisions." The example is Cursor, an AI coding company, whose losses came from people who opened accounts, used free credits and never paid. As Nate B. Jones puts it, "By the time a conventional payment fraud system had something to evaluate, the compute had already been spent." In the interview, Stripe describes a shift from scoring payments to judging customers at sign-up, trial start and overage. Stripe also says fraud models for agent purchases need different inputs, because an agent moves through a purchase differently from a person. These accounts come from Stripe's own staff. Banks score card purchases on the issuing side, and on Stripe's account the buyer those fraud models were built around is changing.

Nate B. Jones via Substack (shared by Nate B. Jones)

Netherlands & Sovereignty

The Dutch cabinet puts 120 million euros into a European AI project and scales back its own AI plans. Authority

A letter to Parliament from the State Secretary for digitalisation, dated 21 September and entered in the record on 28 September, sets out the cabinet's AI agenda. The cabinet makes 120 million euros available for Dutch participation in an Important Project of Common European Interest for AI. That is an EU route for state-aided joint projects. It also backs the Groningen AI Factory, a national AI supercomputing centre. A further 2.4 million euros over four years goes to an EU marketplace of AI building blocks for public bodies. The same letter says no extra central money exists to deliver the Dutch Digitalisation Strategy at its published ambition. Some government AI roll-outs will be scaled down, delayed or redesigned, and only a few applications in six priority areas will be scaled up. A report on those choices is due by the end of 2026. The new money goes to a European project and a supercomputer, while shared government AI infrastructure and common AI frameworks stay at the exploration stage with no delivery date.

Eerste Kamer der Staten-Generaal

EIOPA's head warns that swapping non-European AI providers for a few European ones can leave concentration risk in place. Authority

Damian Jaworski, Executive Director of EIOPA, the EU supervisor for insurers and pension funds, published an article on scaling AI in finance on 16 September. It draws on EIOPA's 2025 survey: 65% of 347 insurers in 25 European countries already used generative AI, and 23% planned to. The article warns that advanced AI can amplify cyber and operational risk. The routes it names are faster discovery of software flaws, automated fraud and dependence on a few providers. Replacing non-European suppliers with a small number of European ones may leave that concentration in place. Firms are asked to map their AI dependencies, test provider and model failures, and prove that exit plans work. The article favours strict use of DORA, the EU's digital resilience law, and the AI Act over a new AI law for finance. Sovereignty and resilience are often argued as one goal, and here a European supervisor's head treats them as two separate questions.

European Insurance and Occupational Pensions Authority

Bruegel projects Europe will still hold only about 6% of the world's AI computing power in 2031. Institute

The Brussels think tank Bruegel published a policy brief on 10 September on Europe's shortfall in AI computing capacity. It uses the Europe2031.ai dataset of public projects. Europe had 2.07 gigawatts in 2026, 5% of a 45-gigawatt world total, against 35.28 gigawatts in the United States. By 2031 Europe reaches 20.89 gigawatts, about 6% of 373 gigawatts. The dataset leaves out capacity that US cloud providers already run in EU data centres, so Europe's real share is somewhat higher. Bruegel names grid connections and speed to operation, not private capital, as the tightest near-term limits. It also warns that strict local-content rules could deter supply. Any European sourcing option the bank weighs draws on a pool that, on these projections, stays about a twentieth of world capacity through 2031.

Bruegel: How can Europe address its pressing AI compute infrastructure shortfall?

A World Economic Forum playbook asks lenders to underwrite AI data centres on power, water and local consent. Institute

The World Economic Forum and Oliver Wyman published a decision playbook for AI data centres in September, which Tony Moroney shared on 27 September. It names six constraints on whether a site stays viable: electricity, water, cooling, community acceptance, land and regulation. At least 75 US projects worth about 130 billion dollars were blocked or delayed in the first quarter of 2026. New York paused new sites above 50 megawatts in July. The report applies a 10 to 15% blocked-project rate to a McKinsey estimate of 7 trillion dollars of investment to 2030. On that basis, 700 billion to 1 trillion dollars could be delayed or cancelled. A chapter for financial institutions asks lenders to build grid, water, climate and community risks into due diligence. It also asks them to tie loan terms to improvement over time. Amsterdam sits with Seoul and Dublin among markets shaped by policy and grid allocation. For a bank lending to data-centre developers and their suppliers, those local constraints now sit inside repayment risk.

World Economic Forum and Oliver Wyman via LinkedIn (shared by Tony Moroney)

Industry & competition

Santander's AI lab has published an open protocol that limits which company knowledge an agent can find and cite. Corporate

Santander AI Lab published A2K, short for Agent-to-Knowledge, on 23 September. It is an open set of rules for how AI agents inside a company find approved knowledge sources and draw on them. What an agent can discover is tied to the permissions of the person it acts for. Santander says this stops an agent becoming a back door to restricted information. Each answer comes with citations, document versions, freshness data and an audit record. Conflicts between sources are flagged rather than silently settled. Five conformance levels let a firm add controls as data sensitivity rises. Santander published reference code but no evidence from production use. A systemic European bank has published its answer to a question every bank deploying internal agents meets: whose access rights an agent inherits when it reads policies and client files.

Banco Santander

DBS is starting AI agents with corporate clients on a fixed list of actions, and holding retail agents until 2027. Corporate

DBS said on 25 September that its AI assistants reach more than 10 million users in Singapore, Hong Kong and Taiwan. They are DBS Joy for corporate clients and digibot for retail customers. DBS is now adding the first agentic tasks, where the assistant carries out an action rather than answering a question. These are open only to authenticated corporate users and limited to supported actions under authorised instructions. More than 100,000 Hong Kong corporate users are expected to receive them, and retail agent features are planned for 2027. DBS reports a 16% fall in hotline calls since the assistants launched, its own figure. A bank that boards often use as a digital benchmark has made corporate clients the first place its agents act. Those clients already work under signed mandates and approval limits.

DBS Bank (Hong Kong)

Innovation

Microsoft will host apps that staff build with Copilot inside the company's own tenant, with one admin inventory. Vendor

Microsoft put Copilot Managed Runtime into public preview on 25 September. It runs apps that employees generate with Copilot tools, or with compatible third-party builders, inside the company's own Microsoft 365 environment. Access runs through the company's existing Microsoft sign-in. Administrators set which connectors, data and endpoints each app may reach. Microsoft says administrators will also get deployment and version controls, monitoring, usage data and a central list of apps. As a preview, these are announced features rather than tested ones. Apps that business teams build for themselves are hard to count once they spread. A central list of which AI-built apps run, and what data they reach, is the record that end-user computing controls, a bank's rules for tools built outside central IT, depend on.

Microsoft

Security

Anthropic's system card shows Claude Opus 5.5 refuses fewer malicious agent tasks and leans on outside filters. Vendor

Anthropic published a 230-page system card, its pre-release safety report, for Claude Opus 5.5 on 22 September. Tested without extra safeguards, the model refused 79% of malicious requests to operate a computer, against 94% for its predecessor. Anthropic names blocking filters, not the model's own refusals, as its main protection against harm. In an outside test, an attacker made 200 attempts in each of 40 coding scenarios to plant instructions in content the model reads. With injection detectors switched on, at least one attempt still worked in 36 scenarios. Every observed success came through a weaker backup model to which Anthropic routes some blocked requests. Most tests were run by Anthropic itself, some in simulation, and it says the filters are still being tuned. The brief reported the model's price cut on 24 September. The protection a bank gets therefore depends on how the filters and backup model are set on the channel it buys through. A review of the model alone does not see those settings.

Anthropic: Claude Opus 5.5 System Card

A Center for AI Safety paper argues that spreading work across several AI providers does not protect against a poisoned model. Institute

Researchers at the Center for AI Safety, a US non-profit, published AI Deterrence by Betrayal, which Peter Slattery shared on 26 September. The paper argues that rivals, insiders or governments can turn an organisation's AI agents against it. The routes include poisoned training data, hidden triggers planted in a model and legal pressure on the developer. The authors say no reliable method exists to detect such triggers. They cite research in which about 250 poisoned documents were enough to plant one, regardless of model size. Using several model providers adds little protection when an attack hits all of them at once, for example through shared web training data. The paper finds that controls outside the model, which fix what an agent may do, hold even against a fully compromised model. Multi-vendor model strategies are often presented as resilience. On this evidence they reduce dependence on one supplier without reducing the risk of a planted trigger.

Center for AI Safety via LinkedIn (shared by Peter Slattery)

On the radar

  • A fake WhatsApp message and an AI-cloned lawyer's voice let fraudsters move 95 million euros from Fideuram, Intesa Sanpaolo's private bank, and about 36 million euros is still missing, Reuters reported on 25 September. Reuters
  • Milan prosecutors are investigating two further AI-assisted frauds at Italian banks, one in which a bank manager authorised about 24 million euros in transfers, ANSA reported on 25 September. Agenzia Nazionale Stampa Associata (ANSA)

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
← Newer AI Pulse Daily Brief | 2026-09-30 Older → AI Pulse Daily Brief | 2026-09-28
Powered by Buttondown, the easiest way to start and grow your newsletter.